FORTITUDE LEGAL PRIVACY POLICY

 

Our privacy obligations

 

Fortitude Legal is an Australian law firm operating as an incorporated legal practice.

 

Fortitude Legal is governed by the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).  The APPs regulate how personal information is handled by Fortitude Legal.

 

Fortitude Legal’s Privacy Policy applies to personal information collected and/or held by Fortitude Legal.

 

‘Personal information’ means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information or opinion is true or not and whether the information or opinion is recorded in a material form or not.

 

‘Sensitive information’ is a type of personal information that has specific protection under privacy laws. Sensitive information includes information about an individual’s race or ethnic origin, political opinions, religious or philosophical beliefs, sexual orientation or practice, membership of a union or professional or trade association, or criminal record. Health information, and biometric data (such as finger scans, or images used by facial recognition systems), are also protected as sensitive information.

 

‘Health information’ is defined to include information or an opinion about:

(a)                  an individual’s

(i)                   health (including illness, disability or injury);

(ii)                  express wishes about future provision of health services; and

(iii)                 a health service provided or to be provided;

(b)                  Personal information collected for providing health services;

(c)                  Personal information collected about organ, body part or body substance donation;

(d)                 Genetic information that is predictive of an individual or a genetic relative.

 

Additionally, as an organisation in Victoria that is not a health service provider but which nonetheless collects, holds or uses health information, Fortitude Legal is also governed by the Health Records Act 2001 (Vic).

 

We will review this Privacy Policy regularly, and we may update it from time to time.

 

The types of personal information we collect and hold

 

We may collect the following types of personal information about our clients, and other individuals who submit enquiries with our firm, as part of our routine activities:

 

  • Name, signature, address, telephone number, email address, date of birth
  • Photographs or videos
  • Identification documents or numbers such as passport or driver’s licence
  • Medical records and other health information including diagnosis and treatments
  • Bank or credit card details
  • Financial history and taxation records
  • CCTV footage
  • Social media activity

 

We also collect personal information about our staff, contractors and suppliers, and other types of professional associates and personal contacts.

 

How we collect personal information

 

Information that you specifically give us

We may ask you to provide us with certain types of personal information if you wish to obtain a particular service from us. This might happen over the telephone, through our website, by filling in a paper form, or meeting with us face-to-face. We will give you a Collection Notice at the time, to explain how we will use the personal information we are asking for. The notice may be written (in hard copy or digital form) or verbal.

 

You might also provide your personal information to us, without us directly asking for it, for example if you engage with us on social media.

 

Information that we collect from others

If you apply for a job or contract with us, we will collect personal information about you from your referees. With your consent we may also use a third-party service to ensure your employment, educational and identity records are valid. We may also check some details about our suppliers from publicly available sources, such as the Australian Business Register and ASIC databases.

 

Information that we generate ourselves

We maintain records of the interactions we have with our clients, and other individuals who submit enquiries with our firm, including the services we have provided to you, or complaints you have made.

 

We collect limited information about users of our websites, for diagnostic and analytic purposes. We use cookies and gather IP addresses to do so, but we do not trace these back to individual users.

 

We collect personal information from users of our websites if they complete webforms or ‘claim checker’ bots, including name, phone number, email address and nature of their enquiry.  A Fortitude Legal staff member may contact you where a webform or ‘claim checker’ bot has been completed.

 

Links to other sites

On our website, we may provide links to third-party websites. These linked sites are not under our control, and we cannot accept responsibility for the conduct of companies linked to our website. Before providing your personal information via any other website, we advise you to examine the terms and conditions of using that website and its privacy policy.

 

How we use personal information

 

We may use your personal information for the following purposes:

  • to provide the service you have requested
  • to process payments made to us
  • to provide technical or other support to you
  • to answer your enquiry about our services, or to respond to a complaint or feedback
  • to manage our employment or business relationship with you
  • to promote our other services which may be of interest to you (unless you have opted out from marketing communications)
  • to comply with legal and regulatory obligations
  • if otherwise permitted or required by law, or
  • for other purposes with your consent, unless you withdraw your consent.

 

When we disclose personal information

 

Our third-party service providers

The personal information of our clients, staff, suppliers and other contacts may be held on our behalf outside Australia, including ‘in the cloud’, by our third-party service providers. Our third-party service providers are bound by contract to only use your personal information on our behalf, under our instructions.

 

Other disclosures and transfers

  • Our related companies (international branches, subsidiaries etc. Include details of their legal name(s) and ABN(s))
  • Financial institutions processing payments
  • In case of the sale of the business (in whole or in part), to the purchaser (as an asset of the business)
  • For job applicants, referees whose details you provide to us
  • To law enforcement agencies in the event of …
  • To carers
  • To other health service providers
  • To relevant Government Authorities necessary to pursue claims for compensation including but not limited to the Transport Accident Commission, WorkCover/ WorkSafe, Courts and Tribunals, and Medical Panels.

 

We may also disclose your personal information to third parties for the following purposes:

  • if necessary to provide the service you have requested
  • if otherwise permitted or required by law; or
  • for other purposes with your consent.

 

Security and retention of your personal information

 

We will take reasonable security measures to protect personal information from loss, unauthorised access, use, modification or disclosure.  We store information in access-controlled premises or in electronic databases requiring secure login credentials and data encryption.  All partners, staff and third-party providers with access to confidential information are subject to confidentiality obligations.

 

Clients and users of our website should only rely on communications sent from our official contact details listed on our website, and if you receive a suspicious or unexpected communication claiming to be from our firm, please contact our office directly to verify its authenticity and report the matter immediately.

 

We will take reasonable steps to ensure personal information is stored securely in our computer systems or in physical form, and in some instances through external service providers, not kept longer than necessary, and disposed of appropriately.

 

We will keep personal information about you, to use for the purposes outlined above (see ‘How we use personal information’), or where a specific law requires us to retain it for a given period or for another purpose.

 

We retain an electronic record of all matters and enquiries for up to 7 years after finalisation of the matter.

 

Physical documents are retained and held in the safe custody of Fortitude Legal during the life of a matter, and are also stored electronically.

 

At the conclusion of a matter, necessary physical documents are either returned to a client or destroyed 7 years after the matter has concluded in accordance with law.

 

Accessing or correcting your personal information

 

You have the right to request access to the personal information Fortitude Legal holds about you. Unless an exception applies, we must allow you to see the personal information we hold about you, within a reasonable time period, and without unreasonable expense.

 

You also have the right to request the correction of the personal information we hold about you. We will take reasonable steps to make appropriate corrections to personal information so that it is accurate, complete and up-to-date.

 

Unless an exception applies, we must update, correct, amend or delete the personal information we hold about you within a reasonable time period.  We do not charge for making corrections.

 

To seek access to, or correction of, your personal information, please contact our Privacy Officer.

 

Automated decisions

 

Automated decisions are processes in which a decision is made either entirely or substantially by a computer program.

 

Fortitude Legal does not use the personal information we hold in automated decision-making processes.

 

To contact our Privacy Officer

 

If you have an enquiry or a complaint about the way we handle your personal information, or to seek to exercise your privacy rights in relation to the personal information we hold about you, you may contact our Privacy Officer as follows:

 

OUR PRIVACY OFFICER IS:

Katalin Blond

Managing Director

 

Telephone: 1300 020 618

Email: info@fortitudelegal.com.au

Mail: PO Box 422, BALLARAT VIC 3353

 

While we endeavour to resolve complaints quickly and informally, if you wish to proceed to a formal privacy complaint, we request that you make your complaint in writing to our Privacy Officer, by mail or email as above. We will acknowledge your formal complaint within 3 working days from date of receipt of your formal complaint.

 

If we do not resolve your privacy complaint to your satisfaction, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) by calling them on 1300 363 992, making a complaint online at www.oaic.gov.au, or writing to them at OAIC, GPO Box 5218, Sydney NSW 2001.